VDB
CVE-2007-5381
CVE-2007-5381
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to execute arbitrary code by setting a long hostname on the target system, then causing an error message to be printed, as demonstrated by a telnet session to the LPD from a source port other than 515.
EPSS 60.31% · 98.3th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
60.31%
98.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | ios | *, *, * |
| n/a | n/a | n/a |
Timeline
- Oct 10, 2007 CVE Published
- Oct 10, 2007 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- 20071010 Cisco IOS Line Printer Daemon (LPD) Protocol Stack Overflow vendor-advisory
- 37935 vdb
- 27169 third-party-advisory
- ADV-2007-3457 vdb
- cisco-ios-lpd-bo(37046) vdb
- http://www.irmplc.com/index.php/155-Advisory-024 url
- VU#230505 third-party-advisory
- 1018798 vdb
- 26001 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2007-5381 advisory